Privacy notice

This notice explains how NodeService Path Advisory handles personal data when you contact the desk or when employee data appears in working papers. We follow Malaysia’s Personal Data Protection Act 2010 (PDPA).

Data user

NodeService Path Advisory, Persiaran Damai, Seksyen 11, Shah Alam, Selangor, 40100. Email engagements@nodeservicepath.digital or call +60 03 4256-7754 for access, correction, or withdrawal of consent where the PDPA allows it.

What we collect from enquiries

The contact form asks for your name, organisation, email, phone, the payroll suite you use, and a message. That data is used to reply with a scoping letter and to keep a short enquiry record. We do not sell it. We do not use it for automated decision-making.

What we collect during fieldwork

Engagements may include employee identifiers, wage types, bank-account references, and statutory numbers to the extent needed to rebuild pays and match files. We prefer redacted extracts. Where live data is unavoidable, it is processed as a data processor for your organisation under the engagement letter, for the purpose of the financial audit of the application only.

Sources

You, your authorised payroll or finance staff, and the controlled exports you provide. We do not scrape public profiles to build a marketing list.

Sharing

We share enquiry data with no one except where the law requires it. Working papers are not shown to other clients. If a statutory authority lawfully demands papers, we will tell you unless we are forbidden to do so.

Retention

Unsuccessful enquiries are kept for 24 months. Signed engagement files and working papers are kept for seven years, then destroyed. Cookie preference is stored only on your device; see cookies.

Transfers

The practice is in Malaysia. We do not send employee-level working papers outside Malaysia. If an enquiry email is processed by a mail host, we choose a host that can keep the mailbox in-region or under a PDPA-appropriate contract.

Your rights

You may request access to and correction of your personal data, and you may limit processing where the PDPA gives you that right. Employee data in working papers is usually handled through the employer who commissioned the engagement. Complaints may be directed to us first, then to the Personal Data Protection Commissioner.

Security

Papers are kept in a locked cabinet and on encrypted disks at the Shah Alam desk. Named accounts, not shared logins, are used on our own machines — the same standard we ask of payroll suites.